Anomaly detection of internet of medical things cyberattacks using federated learning

Abstract Devices connected to the Internet of Medical Things (IoMT) handle sensitive patient data under strict privacy and resource constraints. Centralized intrusion detection introduces privacy risks and communication bottlenecks, while existing Federated Learning (FL) solutions struggle with class imbalance and data heterogeneity. This paper proposes One-Shot Federated Anomaly Detection (OneShot-FedAD), which completes feature selection and model training in a single communication round, eliminating iterative weight exchange. It integrates Federated Differential Privacy Mutual Information (DP-MI) for feature selection, local Synthetic Minority Oversampling Technique (SMOTE) to reduce false alarms without sharing raw data, and Adaptive Weighted Aggregation (AWA) based on each client’s local validation F1-score. Across seven experiments on CICIoMT2024 and WUSTL-EHMS-2020, LightGBM achieves 99.75% accuracy and 99.87% F1-score on CICIoMT2024, stable across five random seeds (99.88% ± 0.01%, 95% CI), and 93.77% accuracy with 55.70% attack recall on WUSTL-EHMS-2020, reflecting severe class imbalance on this smaller dataset. DP-MI reduces the feature space by 28.57–44.44%. With per-client uploads under 350 KB, a 1.7 MB aggregated model, and 9.01–24.14 µs inference latency (72–193 µs under an 8 $$\times $$ hardware slowdown), OneShot-FedAD is feasible on 512 MB edge devices.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-09-30
DOI
https://doi.org/10.1038/s41598-026-69924-2
Primary Topic
Anomaly Detection Techniques and Applications
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Anomaly detection of internet of medical things cyberattacks using federated learning

Ahmed Aljughaiman, Sarah Alfayz, Maha AlMarri
Scientific Reports
Anomaly Detection Techniques and Applications
article

Anomaly detection of internet of medical things cyberattacks using federated learning

Ahmed Aljughaiman, Sarah Alfayz, Maha AlMarri
article en

Abstract

Abstract Devices connected to the Internet of Medical Things (IoMT) handle sensitive patient data under strict privacy and resource constraints. Centralized intrusion detection introduces privacy risks and communication bottlenecks, while existing Federated Learning (FL) solutions struggle with class imbalance and data heterogeneity. This paper proposes One-Shot Federated Anomaly Detection (OneShot-FedAD), which completes feature selection and model training in a single communication round, eliminating iterative weight exchange. It integrates Federated Differential Privacy Mutual Information (DP-MI) for feature selection, local Synthetic Minority Oversampling Technique (SMOTE) to reduce false alarms without sharing raw data, and Adaptive Weighted Aggregation (AWA) based on each client’s local validation F1-score. Across seven experiments on CICIoMT2024 and WUSTL-EHMS-2020, LightGBM achieves 99.75% accuracy and 99.87% F1-score on CICIoMT2024, stable across five random seeds (99.88% ± 0.01%, 95% CI), and 93.77% accuracy with 55.70% attack recall on WUSTL-EHMS-2020, reflecting severe class imbalance on this smaller dataset. DP-MI reduces the feature space by 28.57–44.44%. With per-client uploads under 350 KB, a 1.7 MB aggregated model, and 9.01–24.14 µs inference latency (72–193 µs under an 8 $$\times $$ hardware slowdown), OneShot-FedAD is feasible on 512 MB edge devices.

Scientific Reports
King Faisal University (SA)
Peace, Justice and strong institutions
Openalex Percentile: Top 68%
Anomaly Detection Techniques and Applications
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Anomaly detection of internet of medical things cyberattacks using federated learning — Ahmed Aljughaiman, Sarah Alfayz, et al. · Scientific Reports (2026) | TGRS Research Map | TGRS